HIGH
CVE-2020-13323
CVSS
7.7
Description
A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos
Summary dbcve.org
This is an information disclosure vulnerability in GitLab where private merge requests could be read through the Todos feature by unauthorized users. Under certain conditions, the access control intended to protect private merge requests could be bypassed, allowing users to view merge request details they should not have access to.
Mitigation
Upgrade GitLab to version 13.1 or later to remediate this vulnerability.
EPSS Score
1.1%
Probability of exploitation in next 30 days
64.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.